26 Feb 25. Radisys® Corporation, a global leader of open telecom solutions, today announced a new partnership with SEMPRE, specializing in hardened digital infrastructure made in the USA. This partnership focuses on developing advanced and ruggedized technology to deliver secure and resilient O-RAN networks for military and civilian use. Radisys’ cutting-edge open RAN solution and proven expertise in network modernization are seamlessly integrated with SEMPRE’s state-of-the-art design to deliver a robust tactical network designed to connect authorized devices within highly secure environments, ensuring unparalleled reliability and protection. Together, they are delivering secure, resilient 5G networks designed to keep defense and commercial operations connected when it matters most. SEMPRE revolutionizes connectivity with an easy-to-deploy and manage decentralized network. From hardware to software, the architecture is built on an uncompromising security-is-everything principle. Designed for global scalability, this solution leverages Radisys’ 3GPP and O-RAN compliant 5G RAN software, supporting multiple frequency bands to deliver secure, high-capacity, high-performance networks for defense and commercial customers. SEMPRE provides integrated private 5G, edge computing, hybrid cloud access and satellite connectivity in a hardened enclosure that is designed to operate independently or with existing networks. SEMPRE’s patented satellite-based control plane and air-gapped management system ensure secure data transmission and real-time monitoring in any environment. This guarantees uninterrupted, secure communication for defense and commercial users—anytime, anywhere. Radisys 5G CU/DU software won the final stage awards in the U.S. DoD/NTIA 5G Challenge 2022 and 2023 editions, including the award for best SBOM in 2022. Radisys has been a trusted RAN vendor for many ruggedized defense and public safety deployments with highly optimized footprint and ready portability on multiple platforms leveraging hardware and software security features to provide secure and robust 5G connectivity.
“Over the past year, SEMPRE has worked closely with Radisys to optimize its O-RAN stack for security and survivability, ensuring it can operate in both centralized and decentralized configurations,” said Rob Spalding, CEO of SEMPRE. “This collaboration expands the boundaries of survivable cellular networks, and we’re excited about the innovations ahead.”
“Securing communications infrastructure and ensuring its availability at all times is absolutely critical to defense and public safety networks, and we are delighted to partner with SEMPRE in delivering this promise,” said Arun Bhikshesvaran, CEO of Radisys. “Our partnership ensures continued service, even under adverse conditions, offering both immediate and long-term value in terms of security, uptime, and operational continuity, essential for defense and national security operations. We look forward to continuing this collaboration to deliver innovative and security-hardened solutions for defense and commercial networks.”
About Radisys
Radisys is a global leader in open telecom solutions and services. Its disaggregated platforms and integration services leverage open reference architectures and standards combined with open software and hardware, enabling service providers to drive open digital transformation. Radisys offers an end-to-end solutions portfolio from digital endpoints to disaggregated and open access and core solutions to immersive digital applications and engagement platforms. Its world-class and experienced network services organization delivers full lifecycle services to help service providers build and operate highly scalable and high-performance networks at optimum total cost of ownership. For more information, visit www.Radisys.com.
About SEMPRE
SEMPRE delivers mission-critical connectivity with private 5G, high-performance edge, hybrid cloud access and a SATCOM gateway—all in one easy-to-operate, hard-to-destroy system. Whether the mission requires a permanent network or transportable one that’s fully operational in 10 minutes, SEMPRE ensures resilient, secure communication when it matters most. SEMPRE ensures you can deploy anywhere and operate everywhere. For more information, visit www.sempre.ai.
Radisys® is a registered trademark of Radisys. All other trademarks are the property of their respective owners. (Source: BUSINESS WIRE)
26 Feb 25. ‘Zero Trust’ Architecture Could Prevent Adversary Data Theft, Protect Warfighters. Without the right level and right kind of cybersecurity architecture in place, adversary nations will continue to infiltrate U.S. military and partner networks, including contractors within the defense industrial base, and steal important information, which may include details on weapons systems.
The Defense Department’s Zero Trust architecture, expected to reach “target level” implementation in fiscal year 2027, will protect military networks from adversaries. By that time, DOD anticipates having implemented 91 of the 152 target activities that were identified in the department’s Zero Trust Strategy and Roadmap, which was released in 2022.
A Zero Trust architecture is one that assumes no one who uses the network can be trusted. In such a setup, users might be allowed access only to information and applications they are authorized to use. Past network security might have put a wall around the whole network, and once inside, a user would have free rein within the system. In a Zero Trust environment, users must regularly prove they are authorized to see and interact with data, applications and resources.
With just over 2.5 years left before fiscal year 2027, the department has made progress toward reaching its Zero Trust goals — but more has to be done, said Marine Corps. Col. Gary Kipe, chief of staff of DOD’s Zero Trust Portfolio Management Office.
“We have 31 months until we hit FY27,” Kipe said Feb. 19, 2025, during the Zero Trust Summit in Washington. ” the latest analytical review of the implementation plans that we have received back from across the enterprise, we’re doing well, but we’re not anywhere close to being done.”
According to the Zero Trust PMO, current data shows that across all 58 components, 14% of target level Zero Trust activities have been completed across DOD.
Two areas where Kipe said the department needs to get ahead, and soon, involve implementation of a federated identity, credential and access management, or ICAM, solution as well as adoption of data tagging standards and their implementation.
“If we don’t have that, we’re going to get all the way to the end and not have the final push across the finish line,” he said.
A data tagging and labeling standard is a structured framework that defines consistent metadata, classification and access-control attributes for actors across the enterprise. When data owners appropriately tag data, it becomes possible for appropriate data access controls to be put in place. A federated ICAM solution allows the identities of users to be centrally managed to ensure authorized and authenticated access across DOD platforms.
According to the Zero Trust PMO, several funded efforts are underway to advance both a federated ICAM solution and a data tagging and labeling standard.
While Zero Trust is meant to protect Defense Department networks, it’s not just about protecting data. It’s also about protecting those who use and depend on data, including warfighters.
“Zero Trust ensures warfighters receive secure, real-time mission data while denying adversaries access to critical systems, even if networks are compromised,” Kipe said. “By enforcing continuous authentication and microsegmentation, it prevents unauthorized access, insider threats and cyberattacks from disrupting operations. This means faster, more reliable intelligence, communications and logistics, directly enhancing combat effectiveness and survivability in contested environments.” (Source: U.S. DoD)
25 Feb 25. Botnet-operated password-spray attacks point to raised security risks for Microsoft 365 users. On 24 February, the security company SecurityScorecard reported that a botnet (defined as a network of personal/private devices infected with malicious software and operated as a whole without the owners’ knowledge) is conducting password-spray attacks against global Microsoft 365 (M365) accounts. The botnet uses stolen credentials (likely previously obtained via information-stealing malware) to attempt to infiltrate a large number of user accounts. The attacks specifically target accounts using basic authentication processes (entering plaintext login credentials). This enables the threat actors to log into accounts without the need for any additional identity verification (such as multi-factor and other token-based authentication methods). The botnet’s infrastructure and time zone suggest it is possibly operated by China-based threat actors, though the motivation behind the attacks remains unclear. The botnet comprises approximately 130,000 compromised devices, underscoring the scale of the operation. Microsoft plans to disable basic authentication for most M365 services in September in an attempt to mitigate against long-term security risks. However, we assess there remains short-to-medium-term security risks facing global M365 users operating with basic authentication processes. (Source: Sibylline)
25 Feb 25. Thales launches cortAIx in the UK with 200 experts in AI for critical systems.
- Thales marks a new major milestone in its global acceleration in trusted AI with the launch of cortAIx in the UK to address defence and security domains.
- With 200 new highly skilled AI and data specialists, this local antenna of cortAIx will support the UK Government’s vision for AI-driven growth and productivity, thus contributing to a global workforce of 800 experts in AI within the Group.
- This initiative will strengthen the AI ecosystem, serving the performance of sovereign advanced systems and sensors in the most challenging and constrained environments.
The new centre will reinforce Thales’ commitment to advancing the ethical and effective use of AI to address complex challenges. It will enhance domestic AI capability in line with the UK Prime Minister’s recent announcement of the AI Opportunities Action Plan.
AI is transformational and pervasive, providing incredible new capabilities that are reshaping our daily lives. However, it can also be exploited by hostile actors, creating instability and undermining our society. The UK seeks to embrace the opportunities offered by AI, deploying it as a force for good to uncover valuable hidden insights in the vast swathes of data that surround us and leveraging it to provide security and deterrence against adversaries.
Thales Group’s global cortAIx initiative already employs over 600 AI and data specialists, being the first patent applicant in AI for critical systems in Europe with more than 200 patents filed to date. With more than 100 products integrating AI, the Group accelerates the development and deployment of trusted AI-powered systems in the most complex and challenging environments. cortAIx in the UK builds on this success and will serve as a focal point for AI innovation, bringing together cutting-edge technology, talent, and research to deliver AI solutions that are ethical, transparent, explainable, and operationally effective.
A Centre for Innovation and Sovereign Capabilities
Thales will leverage its deep expertise in defence and security to create AI solutions tailored to the UK’s specific operational needs – from the edge to the cloud.
cortAIx in the UK will develop AI solutions that will:
- enhance decision-making for human operators, even under the most challenging and constrained circumstances;
- improve the performance of the most advanced systems;
- ensure AI is deployed ethically, securely, and transparently.
Driving Skills, Jobs, and Opportunities
Thales is committed to growing the UK’s AI talent pipeline. By the end of 2025, cortAIx in the UK will sustain 200 highly skilled AI and data specialist roles, supporting the UK Government’s vision for AI-driven growth and productivity.
The Group’s R&D already represents £4bn annually, with a significant focus on AI. cortAIx in the UK will leverage this to:
- identify and develop the most promising AI-based technologies;
- support the next generation of AI professionals;
- expand upskilling initiatives with academia and industry;
- ensure the UK retains a sovereign AI capability for national security and industrial growth.
AI in Action
Thales is already deploying AI across multiple systems, including:
- Maritime Mine Countermeasures (French and UK programme MMCM) – AI-powered systems enabling ten times faster area coverage and four times faster detection and classification of mines than traditional crewed systems.
- Digital Crew Computer Vision System – Machine learning-driven object classification and prioritisation to enhance mission support and operational efficiency.
- Maritime Sensor Enhancement (MSET) contract – Enhancing data-driven analytics to maximise system availability and increase operational effectiveness at sea.
“cortAIx in the UK is a major step forward, building on the AI capabilities we already deploy and significantly accelerating the time needed to integrate AI into Thales systems. By aligning with the UK Government’s AI Opportunities Action Plan, cortAIx in the UK will drive innovation, enhance skills, and sustain high-value jobs. It will champion the ethical deployment of AI in regulated environments, ensuring transparency and trust. This will have a very positive impact on the UK security and defence industry” said Phil Siveter, CEO of Thales UK.
Strategic Partnership with Faculty AI
As part of the cortAIx launch in the UK, Thales is strengthening its partnership with Faculty AI, a leader in AI safety and data science. Together, this partnership will:
- accelerate AI research exploitation in critical environments;
- industrialise deep learning for pattern analysis, starting with maritime security;
- enable AI deployment across defence, infrastructure, and public sectors.
“We’ve used AI to solve frontline problems for a decade and are world-leading experts in this field. That’s why we’re trusted by defence clients as well as governments to apply AI safely and ethically to keep citizens safe. We’re excited and proud to be working with Thales’ cortAIx in the UK Centre on mission-critical AI systems” said Marc Warner, CEO of Faculty AI.
Strengthening the UK AI Ecosystem
Thales recognises that a thriving AI ecosystem is essential for the UK to remain globally competitive. Through cortAIx in the UK, we are actively working to build a collaborative AI network that brings together industry, academia, SMEs, and government partners.
By working together, we can:
- drive AI innovation that supports sovereign UK capabilities;
- ensure AI is developed and deployed in a trusted, ethical, and explainable manner;
- strengthen the UK’s position as a leader in AI for national security and industrial growth.
Thales invites partners, customers, and stakeholders to join us in shaping the future of AI in safety-critical and high-security environments, ensuring the UK maintains its edge in trusted AI innovation.
About Faculty AI
Faculty is a leading applied AI company dedicated to delivering impactful artificial intelligence solutions across multiple industries. They partner with organisations to enhance performance through cutting-edge AI, driving real-world impact in mission-critical applications.
24 Feb 25. As a company that has been present in the United Arab Emirates for over 40 years, ELT Group today participated, through its President and CEO Enzo Benigni, in the Italy-United Arab Emirates Business Forum with a speech on the panel ‘Shaping Innovation: Shaping the Future. Strategic Industries’, dedicated to the topic of technological innovation for solutions to global security challenges.
In this context, the long path of collaboration with the country and ELT’s strategic vision have been reaffirmed and underscored by a major step forward at the recent IDEX defence exhibition. This has been realised over time through three milestones: a partnership with ETIMAD, an agreement with Khalifa University, and finally an MOU with EDGE Group. Through these partnerships, the company aims to increase local expertise in knowledge, technical support, maintenance, production and supply chain with reference to the Electronic Defence sector. The ultimate goal is to contribute to the building of a sovereign UAE ecosystem by fostering the growth of local infrastructure.
Cy4Gate, a Group investee with a reputation for excellence in cyber intelligence and cyber security, is also involved in this journey as a strategic enabler in all domains, where the acquisition, management and protection of information are decisive factors for defence and security.
In 2023, ELT had already signed an MOU with ETIMAD, an Emirates-based advanced technology solutions and services company, for an integrated logistics support (ILS) hub for electronic defence (EW) systems, which was inaugurated just a few days ago at the IDEX defence exhibition.
In 2024, an agreement was signed with Khalifa University of Science and Technology to establish the Electro-Magnetic Spectrum Application (EMSA) Lab. This lab will play a central role in knowledge enhancement and research and development in the field of electromagnetic spectrum applications.
Furthermore, also at the recent IDEX exhibition, an MOU was signed with EDGE to pursue the possible establishment of a JV for joint activities related to electronic defence across multi-domains.
At the Italy-UAE Business Forum, this collaboration was further reaffirmed in a Letter of Intent (LOI) signed in the presence of the highest representatives of the two countries, the Prime Minister of Italy, Giorgia Meloni and the President of United Arab Emirates, Sheikh Mohammed bin Zayed Al Nahyan.
Enzo Benigni, CEO of ELT Group, said: “The recent agreements reinforce an already solid partnership and create the opportunity for common growth in the search for challenging solutions to modern global security challenges. At the same time, they allow ELT Group to return to the country a complete product in terms of knowledge and critical technologies”.
21 Feb 25. Cyber Update Key points.
- A new and highly sophisticated malware variant (‘FinalDraft’) has elevated the cyber espionage risks facing global government and telecommunications sectors (see Sibylline Cyber Daily Analytical Update – 17 February 2025).
- The Chinese state-sponsored group ‘Earth Preta’ is targeting Thai-speaking Windows users in a cyber operation, thus raising long-term security and espionage risks .
- A new version of the ‘Snake’ keylogger malware has elevated the security and information-theft risks facing Windows users in the Asia-Pacific and Europe regions.
- A new ransomware variant (‘NaiLaoLocker’) has underscored the long-term security and disruption risks facing the European healthcare sector.
- A new custom tool (‘JumbledPath’) has underscored the long-term elevated security and cyber espionage risks stemming from the Chinese state-sponsored group ‘Salt Typhoon.’
Technical analysis of weekly stories
Unnamed threat actors are targeting Windows users in the Asia-Pacific and Europe regions with a new version of the Snake keylogger malware. Threat actors typically distribute Snake via phishing emails to trick potential victims into opening a malicious link and/or attachment. The attachment contains malicious code that executes the malware via process hollowing; namely, it replaces the original code within a legitimate process with Snake’s malicious code, thus executing the payload while remaining obfuscated. Snake is written in the AutoIt scripting language, allowing threat actors to automate deployment within Windows environments and to hinder detection by anti-virus tools. The keylogger subsequently embeds a copy of the payload within the system’s startup folder, establishing persistence in the event of a system reboot. Snake can steal sensitive information from infected systems and browsers, including credentials, screenshots and credit card details. It then uses Simple Mail Transfer Protocol (SMTP) and Telegram bots to exfiltrate stolen information to the actors’ command-and-control (C2) infrastructure; this enables the threat actors to evade security mechanisms by assimilating with legitimate network traffic. This new version of Snake has made at least 280m blocked infection attempts on devices globally, highlighting the scale and persistent nature of the campaign.
The Chinese state-sponsored group Earth Preta (also known as ‘Mustang Panda’) is targeting Thai-speaking Windows users in a new cyber operation. Earth Preta reportedly uses spear phishing emails to infiltrate targeted systems and to deploy a malicious file containing a malware dropper. The group displays a PDF document requesting users’ co-operation in compiling a government-led anti-crime platform to enhance legitimacy. The dropper then installs a legitimate application from the video game company Electronic Arts (EA) to trigger the covert deployment of a modified variant of the ‘TONESHELL’ backdoor. TONESHELL checks compromised systems prior to execution to identify potential anti-virus tools employed by the security company ESET. Earth Preta subsequently exploits a legitimate Microsoft tool (‘waitfor.exe’) to inject TONESHELL’s code into a legitimate running process by proxy, highlighting the group’s sophistication. This allows Earth Preta to evade detection and establish persistence, as well as to exfiltrate strategic data and conduct additional malicious activities. Alternatively, if no ESET anti-virus tool is identified, the group executes the backdoor directly into the selected running process.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Process hollowing
(Source: Sibylline)

